A Spectral View of Adversarially Robust Features

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Garg, Shivam, Sharan, Vatsal, Zhang, Brian Hu, Valiant, Gregory
Format: Preprint
Published: 2018
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909295338061824
author Garg, Shivam
Sharan, Vatsal
Zhang, Brian Hu
Valiant, Gregory
author_facet Garg, Shivam
Sharan, Vatsal
Zhang, Brian Hu
Valiant, Gregory
contents Given the apparent difficulty of learning models that are robust to adversarial perturbations, we propose tackling the simpler problem of developing adversarially robust features. Specifically, given a dataset and metric of interest, the goal is to return a function (or multiple functions) that 1) is robust to adversarial perturbations, and 2) has significant variation across the datapoints. We establish strong connections between adversarially robust features and a natural spectral property of the geometry of the dataset and metric of interest. This connection can be leveraged to provide both robust features, and a lower bound on the robustness of any function that has significant variance across the dataset. Finally, we provide empirical evidence that the adversarially robust features given by this spectral approach can be fruitfully leveraged to learn a robust (and accurate) model.
format Preprint
id arxiv_https___arxiv_org_abs_1811_06609
institution arXiv
publishDate 2018
record_format arxiv
spellingShingle A Spectral View of Adversarially Robust Features
Garg, Shivam
Sharan, Vatsal
Zhang, Brian Hu
Valiant, Gregory
Machine Learning
Given the apparent difficulty of learning models that are robust to adversarial perturbations, we propose tackling the simpler problem of developing adversarially robust features. Specifically, given a dataset and metric of interest, the goal is to return a function (or multiple functions) that 1) is robust to adversarial perturbations, and 2) has significant variation across the datapoints. We establish strong connections between adversarially robust features and a natural spectral property of the geometry of the dataset and metric of interest. This connection can be leveraged to provide both robust features, and a lower bound on the robustness of any function that has significant variance across the dataset. Finally, we provide empirical evidence that the adversarially robust features given by this spectral approach can be fruitfully leveraged to learn a robust (and accurate) model.
title A Spectral View of Adversarially Robust Features
topic Machine Learning
url https://arxiv.org/abs/1811.06609